Re: Group Policy setting for restricting creation of local user accounts



This is definitely a training issue. Domain Admin rights should not be
handed out haphazardly. You wouldn't make a 5 year old president of the US,
right? Why? Because they have no idea what they're doing.

If these so-called 'admins' need rights within the domain, there are ways to
grant them rights without giving them too much power. i.e. the Delegation
of Control Wizard in A/D, and various groups on workstations.

Ken

"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in message
news:u4v2bLr5GHA.508@xxxxxxxxxxxxxxxxxxxxxxx
Well, you have now significantly changed the scenario.
There is really no way to prohibit a Domain Admin from doing what
they want to do. You can make it more difficult, but your ultimately
cannot do it.

For example, if DA was not in each machine's local Administrators
group, then they could not do anything to those machines - until they
forced their account to again become member in Administrators on
those machines (which they could do).

You probably need to address your issue either by not having as DAs
those that you do not trust to needed extent, and/or by having clearly
stated limits on acceptible/unacceptible actions for DA power usage
with expectation that they will conform to the limits.


"B.E. Jorgenson" <jorgenson.b@xxxxxxxxx> wrote in message
news:1159804569.016570.299160@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Here's the problem.... I have domain administrators that I do not want
creating local users on computers. Would I have to create a restricted
group that mimics domain admins rights minus the right to create local
users?


Roger Abell [MVP] wrote:
"B.E. Jorgenson" <jorgenson.b@xxxxxxxxx> wrote in message
news:1159560514.691170.269170@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Right, but I am looking for a group policy, security template, or
local
security policy.


You could use a restricted group definintion in a GPO applied at an
OU level (not to DC OU or to Domain) that carries definition for
Administrators naming only what you want included in them all.
It is often convenient for that GPO to also had a rename policy set
renaming the built-in Administrator


KenB wrote:
Restricting the users to non-administrator access will prevent them
from
being able to create accounts on the computers.

Ken


"B.E. Jorgenson" <jorgenson.b@xxxxxxxxx> wrote in message
news:1159380582.077768.320930@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Is there a way through group policy to restrict any user from
creating
local computer user accounts when the computer is joined to the
domain?
This has nothing to do with logon locally but actually creating a
local
user account.

Thanks,
Brian







.



Relevant Pages

  • Re: Service accounts best practices
    ... guidance on granting admin accounts. ... >> The only people who should have domain admin rights are the exact people ... >> doing domain admin work and it should be a very small group. ... >>>>Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.win2000.security)
  • Re: What permissions are needed to migrate SID?
    ... The user running ADMT must have Domain Admin rights in the source domain, ... he must have administrator rights on the machine running ADMT. ... One of my customer suggests that it would be best to delegate permissions ...
    (microsoft.public.windows.server.migration)
  • Re: Service accounts best practices
    ... > The only people who should have domain admin rights are the exact people ... > domain admin work and it should be a very small group. ... >>>Joe Richards Microsoft MVP Windows Server Directory Services ... >>>>Can someone point me to a guide to securing service accounts? ...
    (microsoft.public.win2000.security)
  • Re: Domain Admin Server 2003
    ... I no longer have Domain Admin rights and I am not in a privileged group. ... account even though the Domain Admin rights have been taken away. ... >>I had delegated Full rights to my OU's and then was granted Domain Admin ...
    (microsoft.public.security)
  • Re: Adding Computers to the Domain (AD)
    ... computers to a domain with Windows Server 2003! ... > these machines physically in this office. ... If I am correct only someone with domain admin ...
    (microsoft.public.windows.server.setup)